<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ep-patent-document PUBLIC "-//EPO//EP PATENT DOCUMENT 1.2//EN" "ep-patent-document-v1-2.dtd">
<ep-patent-document id="EP04004722B1" file="EP04004722NWB1.xml" lang="en" country="EP" doc-number="1571797" kind="B1" date-publ="20071226" status="n" dtd-version="ep-patent-document-v1-2">
<SDOBI lang="en"><B000><eptags><B001EP>......DE....FRGB................................................................</B001EP><B005EP>J</B005EP><B007EP>DIM360 Ver 2.3  (20 Nov 2007) -  2100000/0</B007EP></eptags></B000><B100><B110>1571797</B110><B120><B121>EUROPEAN PATENT SPECIFICATION</B121></B120><B130>B1</B130><B140><date>20071226</date></B140><B190>EP</B190></B100><B200><B210>04004722.7</B210><B220><date>20040301</date></B220><B240><B241><date>20060227</date></B241><B242><date>20060413</date></B242></B240><B250>en</B250><B251EP>en</B251EP><B260>en</B260></B200><B400><B405><date>20071226</date><bnum>200752</bnum></B405><B430><date>20050907</date><bnum>200536</bnum></B430><B450><date>20071226</date><bnum>200752</bnum></B450><B452EP><date>20070601</date></B452EP></B400><B500><B510EP><classification-ipcr sequence="1"><text>H04L  29/06        20060101AFI20040824BHEP        </text></classification-ipcr></B510EP><B540><B541>de</B541><B542>Befehlsverarbeitungssystem durch einen Verwaltungsagenten</B542><B541>en</B541><B542>Command processing system by a management agent</B542><B541>fr</B541><B542>Système de traitement des commandes par un agent de gestion</B542></B540><B560><B561><text>EP-A- 1 255 179</text></B561><B561><text>US-A1- 2003 115 447</text></B561></B560></B500><B600><B620EP><parent><cdoc><dnum><anum>07016296.1</anum></dnum><date>20070820</date></cdoc></parent></B620EP></B600><B700><B720><B721><snm>Fujita, Takahiro</snm><adr><str>Hitachi, Ltd.
New Marunouchi Bldg.</str><city>5-1, Marunouchi 1-chome
Chiyoda-ku
Tokyo</city><ctry>JP</ctry></adr></B721><B721><snm>Kaneda, Yasunori</snm><adr><str>Hitachi, Ltd.
New Marunouchi Bldg.</str><city>5-1, Marunouchi 1-chome
Chiyoda-ku
Tokyo</city><ctry>JP</ctry></adr></B721></B720><B730><B731><snm>Hitachi, Ltd.</snm><iid>00204151</iid><irf>EPA-41221</irf><adr><str>6, Kanda Surugadai 4-chome</str><city>Chiyoda-ku,
Tokyo 101-8010</city><ctry>JP</ctry></adr></B731></B730><B740><B741><snm>Strehl Schübel-Hopf &amp; Partner</snm><iid>00100941</iid><adr><str>Maximilianstrasse 54</str><city>80538 München</city><ctry>DE</ctry></adr></B741></B740></B700><B800><B840><ctry>DE</ctry><ctry>FR</ctry><ctry>GB</ctry></B840><B880><date>20050907</date><bnum>200536</bnum></B880></B800></SDOBI><!-- EPO <DP n="1"> -->
<description id="desc" lang="en">
<heading id="h0001"><u style="single">Background of the invention</u></heading>
<p id="p0001" num="0001">The present invention relates to a method for managing a computer system in a storage area network environment by means of a management agent.</p>
<p id="p0002" num="0002">One of the most common schemes for managing a computer system is to have a management application and a management agent so arranged that the latter provides the former with a management interface for operating its constituent devices. Thanks to recent advances in the Web technology, use of XML messages is becoming increasingly popular as a means of communication between the management application and the management agent. This kind of arrangement allows the management application to utilize remotely located management agents via the Web (or an ordinary IP network), thereby facilitating centralized management.</p>
<p id="p0003" num="0003">In such an arrangement, the management agent employs user authentication to prevent the settings of the computer system or its constituent devices from being altered by users other than the system administrator. If no security measures such as authentication are employed, a malicious user (cracker) might be able to crack into the system by stealing the system administrator's identity and altering messages during transmission. This might cause the management agent to falsely modify the settings of a device, thereby resulting in a system down.</p>
<p id="p0004" num="0004">In typical conventional arrangements of this sort, the only mechanisms to prevent unauthorized execution of commands on the system's constituent devices have been cryptography, such as a cipher system applied to the communication path between the management application and the management agent, and user authentication. Since<!-- EPO <DP n="2"> --> cryptography in itself does not control the executability of commands on the target device, if it is broken on the communication path the cracker who has also managed to disguise himself/herself as an authorized user would be able to have any commands executed on the target device.</p>
<p id="p0005" num="0005">If for tighter security the management agent were to always demand a sufficiently secure communication path and a sufficiently secure authentication method, then it would become necessary to provide them even for those management applications which do not require such a tight security level. This would limit the management applications that the system administrator can use.</p>
<p id="p0006" num="0006"><patcit id="pcit0001" dnum="EP1255179A2"><text>EP 1 255 179 A2</text></patcit> discloses data security for a distributed data storage system having the features included in the first part of claim 1.</p>
<p id="p0007" num="0007"><patcit id="pcit0002" dnum="US20030115447A1"><text>US 2003/0115447 A1</text></patcit> discloses a network system in which an authentication package determines which particular user is allowed to access an object.</p>
<heading id="h0002"><u style="single">Summary of the invention</u></heading>
<p id="p0008" num="0008">It is an object of the present invention to provide a means for ensuring high security in the management of a computer system by preventing a malicious and unauthorized intruder from executing potent commands that can cause a significant disruption or down of a computer system, without unreasonably limiting the use of the management application by the system administrator.</p>
<p id="p0009" num="0009">This object is met by the computer system defined in claim 1.</p>
<p id="p0010" num="0010">In a preferred embodiment of the present invention, an ad hoc program is introduced which runs on a storage subsystem and which, upon receiving a management command from a system management computer, determines whether it should be executed or rejected, judging from the security level of the communication path from/to the system management computer and the security level required for the execution of the command.</p>
<heading id="h0003"><u style="single">Brief description of the drawings</u></heading>
<p id="p0011" num="0011">
<ul id="ul0001" list-style="none" compact="compact">
<li>Figure 1 illustrates the configuration of a computer system according to the preferred embodiment of the present invention.<!-- EPO <DP n="3"> --></li>
<li>Figure 2 shows an example of the procedures for establishing a ciphered communication path between the management application and the management agent.</li>
<li>Figure 3 shows an example of the layout and contents of four tables (A through D): the security level specification table (A), the required security level table (B), the history table (C), and the security level uplift table (D).</li>
<li>Figure 4 is a flowchart showing the process of how the management agent handles device commands.</li>
<li>Figure 5 is a sample of the table listing SSL3 cipher algorithms.</li>
</ul></p>
<heading id="h0004"><u style="single">Description of the preferred embodiment</u></heading>
<p id="p0012" num="0012">Figure 1 illustrates the configuration of a computer system according to the preferred embodiment of the present invention. A computer system 1 comprises a computer 200a, another computer 200b (these two may also be collectively called a computer 200), a management computer 300, a fiber channel switch 50, an Internet Protocol (hereinafter abbreviated to IP) network 70, and a storage subsystem 400.</p>
<p id="p0013" num="0013">The storage subsystem 400 is connected to the computers 200a and 200b through the fiber channel switch 50 and also to the management computer 300 through the IP network 70.</p>
<p id="p0014" num="0014">The SCSI Protocol over Fiber Channel (hereinafter abbreviated to FCP) is used for data transmission between the computer 200a or 200b and the storage subsystem 400.</p>
<p id="p0015" num="0015">The fiber channel switch 50 comprises a control unit, a memory, a storage unit, interface units 52a, 52b, 52c, and 52d for communication with the storage subsystem 400, and an interface unit 54 for communication with the IP network 70.</p>
<p id="p0016" num="0016">The storage subsystem 400 comprises a control unit 401 and one or more hard disk drives 460. The control unit 401 further comprises a channel adapter 500a and another channel adapter 500b (these two may also be collectively called a channel adapter 500), a cache<!-- EPO <DP n="4"> --> memory 450, a shared memory 590, one or more disk adapters 550, and a crossbar switch 520. The crossbar switch 520 interconnects the channel adapter 500, the cache memory 450, the shared memory 590, and the disk adapters 550. As an alternative, a bus can be used instead of the crossbar switch 520.</p>
<p id="p0017" num="0017">A string of hard disk drives 460 are connected to each disk adapter 550 through a port 570.</p>
<p id="p0018" num="0018">The channel adapter 500a has a processor 510a and fiber channel ports 402a and 402b, through which it receives FCP-based I/O requests issued by computers 200a and 200b, respectively.</p>
<p id="p0019" num="0019">The channel adapter 500b has a processor 510b and IP network ports 404a and 404b. The channel adapter 500b communicates with the management computer 300 through the IP network port 404b.</p>
<p id="p0020" num="0020">The storage subsystem 400 contains one or more logical volumes, each having a logical storage area. Each logical volume corresponds to part or all of the physical storage area that is made up of a string of hard disk drives 460. A logical volume corresponds to a storage area accessible by the computer 200 and is given a unique identification within the computer system 1. The computer 200 issues I/O commands based on FCP against a logical volume.</p>
<p id="p0021" num="0021">The disk adapter 550 transfers data between the string of disk drives 460 connected to it, the cache memory 450, and the channel adapter 500. It also controls the cache memory 450 and the channel adapter 500. For example, it can control the string of disk drives 460 connected to it as a redundant array of inexpensive disks (RAID), thereby enhancing the reliability and performance of the storage subsystem 400.</p>
<p id="p0022" num="0022">To compensate for the low rate of data transfer between the hard disk drives 460 and the channel adapter 500, the storage subsystem 400 holds frequently accessed data in<!-- EPO <DP n="5"> --> the cache memory 450.</p>
<p id="p0023" num="0023">The computer 200a comprises not only a control unit, a memory, a storage unit, and a display unit, just like any other computers, but also an interface unit 202a for connection with the fiber channel switch 50 and an interface unit 204a for connection with the network 70. The computer 200b has a similar configuration.</p>
<p id="p0024" num="0024">The management computer 300 comprises not only a control unit, a memory, a storage unit, and a display unit, just like any other computers, but also an interface unit 304 for connection with the network 70. By loading the management application stored in its storage unit into the memory and executing it, the management computer 300 controls the storage subsystem 400 through the network 70 to which the storage subsystem 400 is also connected. The management computer 300 also communicates with the computer 200 and the fiber channel switch 50 through the network 70.</p>
<p id="p0025" num="0025">Running on the processor 510b, which is part of the channel adapter 500b, is a special program (management agent) for communicating with the management computer 300. It receives setup and control commands from the management application running on the management computer 300, and by executing them, sets up and controls the storage subsystem 400.</p>
<p id="p0026" num="0026">The management agent runs not only on the storage subsystem 400 but also on the fiber channel switch 50 and the computer 200. Thus, the management application running on the management computer 300 can obtain the status of, and modify the settings of, the fiber channel 50 as well as the computer 200 through the management agent running on them.</p>
<p id="p0027" num="0027">The communication between the management application, which runs on the management computer 300, and the management agent, which runs on the channel adapter 500, is based on the Hyper Text Transfer Protocol (HTTP), by which messages written in extensible Markup Language (XML) are exchanged between the two.</p>
<p id="p0028" num="0028">For security reasons, i.e., to prevent eavesdropping, ID theft, and unauthorized<!-- EPO <DP n="6"> --> modification of messages, the communication between the management application and the management agent employs cipher based on the secure sockets layer (SSL) protocol. The SSL protocol, which operates on the TCP/IP protocol, operates underneath higher level protocols such as HTTP (application layer) and enhances the security level of the communication path. SSL's handshaking protocol first determines the cipher algorithm and then establishes a secure communication path.</p>
<p id="p0029" num="0029">Figure 2 describes the procedures for establishing a ciphered communication path using the SSL handshaking protocol between the management application and the management agent, taking SSL3 as an example.</p>
<p id="p0030" num="0030">First, the management application (SSL client) sends "Client Hello" to the management agent (SSL server) (step 1: Client Hello) together with a list of the cipher algorithms supported by the management application and, in the case of resumption of an existing session, the session ID. The list is prioritized according to the order desired by the management application. The management application then waits for "Server Hello."</p>
<p id="p0031" num="0031">Figure 5 is an example of a list of cipher algorithms. For each cipher algorithm, a two-byte ID is assigned.</p>
<p id="p0032" num="0032">The management agent selects one from the list of cipher algorithms sent by the management application and generates a session ID, and then sends "Server Hello" to the management application together with the decision on the cipher algorithm and the session ID (step 2: Server Hello). The management application saves this session ID for later communications, so that by including it in "Client Hello" the management application can, without going through the handshaking protocol, establish a ciphered communication path.</p>
<p id="p0033" num="0033">The procedures for selecting one cipher algorithm are as follows: The management agent, which holds a list of cipher algorithms supported by it, goes through the list of cipher<!-- EPO <DP n="7"> --> algorithms sent from the management application in descending order of priority and checks whether there is a match between the two lists. The first match will be selected.</p>
<p id="p0034" num="0034">Alternatively, the management agent may have its list of supported cipher algorithms sorted by their strength (robustness) and go through this list in descending order of strength to look for a match. This method will result in the strongest algorithm being selected. The strength of a cipher algorithm is basically determined by the length of the cipher key employed. For example, SSL_RSA_WITH_RC4_128_MD5, which uses a 128-bit key, is stronger (more robust) than SSL_RSA_EXPORT_WITH_RC4_40_MD5, which uses a 40-bit key. The preferred embodiment of the present invention uses, as examples of cipher algorithm, SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5 (which is weaker) and SSL_RSA_WITH_RC4_128_MD5 (which is stronger).</p>
<p id="p0035" num="0035">If there is no match between the management application' s list and the management agent's list, or if the management application does not support SSL, then ciphering will not take place.</p>
<p id="p0036" num="0036">Upon receiving a session ID from the management application, the management agent checks the sessions currently in progress for a match in ID. If it finds a session having the same ID, it chooses the cipher algorithm of that session to establish a secure communication path with the management application.</p>
<p id="p0037" num="0037">After step 2, the management agent sends to the management application, as necessary, its own electronic certificate (step 3: Server Certificate), its own public key (step 4 : Server Key Exchange), and a request for the management application' s certificate (step 5: Certificate Request), notifies the management application of the completion of transmission (step 6: Server Hello Done), and waits for a response from the management application.</p>
<p id="p0038" num="0038">Upon receiving "Server Hello Done, " the management application sends its own electronic<!-- EPO <DP n="8"> --> certificate if it has also received "Certificate Request" (step 7: Client Certificate). Then it sends a session key ciphered according to the public key cipher algorithm specified by the cipher algorithm sent with "Server Hello" (step 8: Client Key Exchange). This session key will be used to generate the secret key to be used in the common key cipher in later communication. The management application then sends a message for verifying the management application's certificate (step 9: Certificate Verify) if necessary, notifies the management agent that it is now ready to start ciphered communication using the secret key (step 10: Change Cipher Spec), and finally notifies the management agent of the end of transmission (step 11: Finished).</p>
<p id="p0039" num="0039">Upon receiving "Finished," the management agent notifies the management application that it is now ready to start ciphered communication (step 12: Change Cipher Spec), followed by a notification of the end of transmission (step 13: Finished). The ciphered communication path is thus established.</p>
<p id="p0040" num="0040">Once an SSL-ciphered communication path has been established, the management application running on the management computer 300 sends to the storage subsystem 400 a processing request for the management agent as an XML message, using HTTP Post Request. This XML message contains a command for the storage subsystem 400, which is to be executed by the management agent running on the processor 510b, as will be explained later.</p>
<p id="p0041" num="0041">Figure 3 shows an example of the layout and contents of four tables (A through D): the security level specification table 1000 (A), the required security level table 1100 (B), the history table 1200 (C), and the security level uplift table 1300 (D), which are held in the shared memory 590 and are used by the management agent.</p>
<p id="p0042" num="0042">The security level specification table 1000 assigns a security level to the combination of the cipher algorithm used between the management application and the management agent and the authentication algorithm used by the management agent, and is referenced to<!-- EPO <DP n="9"> --> determine the operational security level between the management application and the management agent.</p>
<p id="p0043" num="0043">In the security level specification table 1000, the "communication path cipher algorithm" means the cipher algorithm for the communication between the management application and the management agent that is determined in step 2: Server Hello. "HTTP" means that SSL-based cipher is not employed.</p>
<p id="p0044" num="0044">In the security level specification table 1000, the "authentication algorithm" refers to the system by which the management agent authenticates the management application. If the client certificate has been received and verified in step 7: Client Certificate during handshaking, "SSL" is entered here. If the client certificate has not been received or verified, a standard HTTP authentication algorithm specified by the Authentication header of the HTTP request message is applicable, which is either Basic based on the user ID and password or MD5Digest. Of the two, Basic, in which the password is sent unmodified over the communication path, is less secure because it can be stolen through wire-tapping or eavesdropping. MD5Digest, in which a hash value calculated from the password is sent instead of the password itself, is more secure because the password itself cannot be stolen. Regardless of the authentication algorithm employed, however, a communication path can be given a high security level if it is based on HTTPS, is ciphered, and is difficult to eavesdrop. In the example of the preferred embodiment described here, for the HTTP that is not ciphered, security level 1 is given to Basic, and security level 2 is given to MD5Digest.</p>
<p id="p0045" num="0045">When HTTPS (SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5) is used as the communication path, the same security level (level 3) is assigned to both Basic and MD5Digest. Also when HTTPS (SSL_RSA_WITH_RC4_128_MD5) is used, the same security level (level 4 in this case) is assigned to both Basic and MD5Digest. If SSL authentication is employed, however,<!-- EPO <DP n="10"> --> higher security levels can be assigned: level 5, for example, when HTTPS (SSL_RSA_WITH_RC4_128_MD5) is used. With HTTPS (SSL_RSA_EXPORT_WITH_RC2_CBC_40_MD5), which does not have strong (robust) enough cipher capability, however, security level 3 is assigned even if SSL authentication is employed.</p>
<p id="p0046" num="0046">The required security level table 1100 lists all the commands that the management application may issue to the management agent, together with the security levels that are required for their execution. This table is referenced to obtain the security level required for the execution of a command received from the management application. The higher the security level, the stronger the cipher algorithm, that is, the safer the communication.</p>
<p id="p0047" num="0047">The security level required of a command, i.e., the security level that is required for the execution of a command, is determined by the possible impact the execution of the command can have on the storage subsystem 400 and the computer system 1. For example, for GetVolumeInfo, a command for obtaining information on the capacity and status of a device (volume) in the storage subsystem 400, the required security level can be low, since its execution would not have any impact on the storage subsystem 400. In contrast, the required security level for AssignVolume, a command for changing the settings of the storage subsystem 400, should be high, since it would allow the storage subsystem 400 to be accessed by the computer 200. Furthermore, the required security level for FormatVolume, a command for formatting or initializing a volume in the storage subsystem 400, should be still higher, since its execution would erase the entire contents of the designated volume, which are being used by the computer 200, thereby rendering the computer 200 inoperable and causing a significant impact on the computer system 1.</p>
<p id="p0048" num="0048">Whereas in the foregoing example of the present invention the required security level is determined by the impact the execution of the command may have on the system,<!-- EPO <DP n="11"> --> alternatively it may be determined also by the importance of the information to be accessed. For example, if the information on the storage subsystem 400 is considered sensitive, then by making the required security level for the GetVolumeInfo command higher, it is possible to prevent unauthorized access to it.</p>
<p id="p0049" num="0049">The history table 1200 records the history of commands issued from the management application to the management agent and has basically four entries per line: the client ID, which is used for authentication by the management application issuing the command, the security level of the communication path established between the management application and the management agent, the security level required of the command executed, and whether the execution has been permitted.</p>
<p id="p0050" num="0050">The security level uplift table 1300 registers the uplift in security level that is to be added to the security level required of the command depending on whether the execution has been permitted (shown in the fourth column in the history table). The uplift value is increased when the command has not been executed because the security level of the communication path was lower than the security level required of the command.</p>
<p id="p0051" num="0051">Figure 4 illustrates how the management agent handles a command issued by the management application. First, the management agent establishes a ciphered communication path using the SSL handshaking protocol described earlier (step 3010). Upon receiving a command from the management application (step 3020), the management agent obtains the security level required for executing it from the required security level table 1100 (step 3030).</p>
<p id="p0052" num="0052">It then obtains the cipher algorithm and the authentication algorithm used in receiving the command (step 3040). The cipher algorithm obtained here is actually the one selected and sent to the management application in step 2: Server Hello of SSL handshaking. If SSL is not used, then this is HTTP.</p>
<p id="p0053" num="0053">The authentication algorithm obtained here is actually the one with which the management<!-- EPO <DP n="12"> --> application has been authenticated: It is either SSL (if the management application (SSL client) has been authenticated in step 7: Client Certificate of SSL handshaking) or is taken from the Authentication header of the HTTP request message received in step 3020 (otherwise).</p>
<p id="p0054" num="0054">Next, using the cipher algorithm and the authentication algorithm obtained in step 3040, it obtains the security level (operational security level) from the security specification table 1000 (step 3050).</p>
<p id="p0055" num="0055">It then obtains the security level uplift value from the security level uplift table 1300 using the client ID of the management application and adds it to the required security level obtained in step 3030 (step 3055).</p>
<p id="p0056" num="0056">It then compares the uplifted required security level (security level required by the client) and the operational security level obtained in step 3050 (step 3060), and if the latter is greater than or equal to the former, executes the command (step 3070); otherwise, it notifies the management application that the command cannot be executed (step 3080).</p>
<p id="p0057" num="0057">In any case, it then registers into the history table 1200 the client ID, and the security level of the communication path, the required security level, and whether the execution of the command has been permitted. If the execution of the command has been rejected, then it increases the uplift value for this client (management application) in the security level uplift table 1300 (step 3090).</p>
<p id="p0058" num="0058">Commands can be targeted at a variety of devices, including the storage subsystem 400, the computer 200, and the fiber channel switch 50. The targeted device stores the security specification table and the required security level table (as shown in Figure 3) in its memory, and determines whether or not to execute the command depending on the result of the comparison between the security level of the communication path and the security<!-- EPO <DP n="13"> --> level required of the command.</p>
<p id="p0059" num="0059">Whereas the preferred embodiment discussed here may appear to assume that the management application resides in the management computer 300 and that only the management computer 300 issues commands to devices, alternative implementations can be envisaged. For example, each of the devices such as the management computer 300, the computer 200, the fiber channel switch 50, and the storage subsystem 400 has a control unit which issues commands for managing other devices, an interface unit which sends such commands to other devices, and a memory which stores a table indicating the security levels of the communication paths and a table defining the security levels required of commands for other devices. In such a configuration, the control unit of each such device can determine whether or not to issue or send a command, based on the result of the comparison between the security level of the communication path and the security level required of such command.</p>
<p id="p0060" num="0060">Alternatively, an arrangement can be made such that the management agent running on the computer 200 is capable of executing control commands on a piece of software such as a database application running on the computer 200 and determines the executability of commands on such piece of software issued by the management application, depending on the security level of the communication path, in the same way as the management agent does for an ordinary device.</p>
<p id="p0061" num="0061">According to the present invention, it is possible to maintain the security of a computer system by preventing a malicious and unauthorized intruder from executing potent commands that can cause a significant disruption or down of it, without unreasonably limiting the use of the management application by the system administrator.</p>
</description><!-- EPO <DP n="14"> -->
<claims id="claims01" lang="en">
<claim id="c-en-01-0001" num="0001">
<claim-text>A computer system comprising<br/>
a computer (200a, 200b),<br/>
a storage subsystem (400), and<br/>
a management computer (300) comprising a control unit (401) adapted to issue commands for managing the computer (200a, 200b) or the storage subsystem (400) and an interface unit (304) adapted to send the commands to the computer (200a, 200b) or the storage subsystem (400);<br/>
wherein the storage subsystem (400) comprises an interface unit adapted to receive commands from the management computer (300) through a communication path (70),<br/>
<b>characterized in that</b> the storage subsystem (400) further comprises a control unit (401) adapted to determine whether to permit the execution of the commands against part or all of the storage area of the storage subsystem (400), based on a security level of the communication path (70) between the management computer (300) and the storage subsystem (400), the control unit (401) including:
<claim-text>a memory (590) storing a first table (1000) pre-registering security levels of the communication path (70) between the management computer (300) and the storage subsystem (400) and a second table (1100) pre-registering security levels required for the execution of commands that the management computer (300) requests the storage subsystem (400) to execute;</claim-text>
<claim-text>first means for obtaining, for each command sent from the management computer (300) to the storage subsystem (400), an operational security level for the command by referencing the first table (1000);<!-- EPO <DP n="15"> --></claim-text>
<claim-text>second means for obtaining, for each command sent from the management computer (300) to the storage subsystem (400), a required security level by referencing the second table (1100);</claim-text>
<claim-text>third means for comparing the operational security level obtained by the first means and the required security level obtained by the second means; and</claim-text>
<claim-text>fourth means for determining whether to permit the execution of the command based on the result of the comparison made by the third means.</claim-text></claim-text></claim>
<claim id="c-en-01-0002" num="0002">
<claim-text>The computer system of claim 1, wherein the control unit (401) of the storage subsystem (400) is adapted to determine whether to permit the execution of the commands against part or all of the storage area of the storage subsystem (400), based also on the type of the commands.</claim-text></claim>
<claim id="c-en-01-0003" num="0003">
<claim-text>The computer system of claim 2, wherein the type of the command is specifically a security level required for its execution.</claim-text></claim>
<claim id="c-en-01-0004" num="0004">
<claim-text>The computer system of claim 3, wherein the security level of the communication path (70) is determined by the kind of cipher algorithm selected in establishing the communication path (70) between the management computer (300) and the storage subsystem (400).</claim-text></claim>
<claim id="c-en-01-0005" num="0005">
<claim-text>The computer system of claim 3, wherein the security level of the communication path (70) is determined by the strength or robustness of the cipher algorithm selected in establishing the communication path (70) between the management computer (300) and the storage subsystem (400).<!-- EPO <DP n="16"> --></claim-text></claim>
<claim id="c-en-01-0006" num="0006">
<claim-text>The computer system of claim 3, wherein the security level of the communication path (70) is determined by the key length of the cipher algorithm selected in establishing the communication path (70) between the management computer (300) and the storage subsystem (400).</claim-text></claim>
<claim id="c-en-01-0007" num="0007">
<claim-text>The computer system of claim 3, wherein the security level required for the execution of the command is determined by the kind of data contained in the storage area that is subject to the operation based on the command.</claim-text></claim>
<claim id="c-en-01-0008" num="0008">
<claim-text>The computer system of claim 3, wherein a higher security level for execution is assigned to commands to delete or erase the contents of the storage area that is subject to the operation based on them than to other commands.</claim-text></claim>
<claim id="c-en-01-0009" num="0009">
<claim-text>The computer system of claim 4, wherein the first table (1000) lists cipher algorithms and authentication algorithms used on the communication path (70) between the management computer (300) and the storage subsystem (400), together with the security level assigned to each combination of cipher and authentication algorithms.</claim-text></claim>
<claim id="c-en-01-0010" num="0010">
<claim-text>The computer system of claim 1, wherein the second table (1100) lists commands defined between the management computer (300) and the storage subsystem (400) together with a security level required for the execution of each of the commands.<!-- EPO <DP n="17"> --></claim-text></claim>
<claim id="c-en-01-0011" num="0011">
<claim-text>The computer system of claim 1, wherein the fourth means is adapted to grant permission for command execution when the comparison made by the third means indicates that the operational security level is greater than or equal to the required security level.</claim-text></claim>
<claim id="c-en-01-0012" num="0012">
<claim-text>The computer system of claim 1, wherein<br/>
the memory (590) further stores a third table (1200) registering a history of the commands issued from the management computer (300) to the storage subsystem (400) and a fourth table (1300) holding for each client ID a security level uplift value determined according to a result of judgment, execution permitted or rejected, recorded in the third table (1200); and the control unit (401) further comprises<br/>
means for adding the security level uplift value obtained from the fourth table (1300) to the required security level obtained by the second means, the required security level thus modified being used in the comparison made by the third means.</claim-text></claim>
<claim id="c-en-01-0013" num="0013">
<claim-text>A method for managing access requests for a storage subsystem (400) comprising:
<claim-text>receiving commands from a management computer (300);</claim-text>
<claim-text><b>characterized by</b> determining whether to permit the execution of the commands against a storage area of the storage subsystem (400), based on a security level of a communication path (70) to and from the management computer (300) and also on a security level required for the execution of the commands, by:</claim-text>
<claim-text>storing a first table (1000) pre-registering security levels of the communication path (70) between the management computer (300) and the storage subsystem (400) and a second table (1100) pre-registering security levels required for the<!-- EPO <DP n="18"> --> execution of commands that the management computer (300) requests the storage subsystem (400), to execute;</claim-text>
<claim-text>obtaining, for each command sent from the management computer (300) to storage subsystem (400), an operational security level for the command by referencing the first table (1000);</claim-text>
<claim-text>obtaining, for each command sent from the management computer (300) to the storage subsystem (400), a required security level by referencing the second table (1100);</claim-text>
<claim-text>comparing the operational security level and the required security level; and</claim-text>
<claim-text>determining whether to permit the execution of the command based on the result of the comparison.</claim-text></claim-text></claim>
<claim id="c-en-01-0014" num="0014">
<claim-text>A computer program for managing access requests for a storage subsystem (400), which, when executed on the storage subsystem (400), performs the method of claim 13.</claim-text></claim>
<claim id="c-en-01-0015" num="0015">
<claim-text>A data carrier readable by a storage subsystem (400) and comprising the computer program of claim 14.</claim-text></claim>
</claims><!-- EPO <DP n="19"> -->
<claims id="claims02" lang="de">
<claim id="c-de-01-0001" num="0001">
<claim-text>Computersystem mit<br/>
einem Computer (200a, 200b),<br/>
einem Speicher-Untersystem (400) und<br/>
einem Verwaltungscomputer (300) mit einer Steuereinheit (401) zur Ausgabe von Befehlen für die Verwaltung des Computers (200a, 200b) oder des Speicher-Untersystems (400) und einer Schnittstelleneinheit (304) zum Übertragen der Befehle an den Computer (200a, 200b) bzw. das Speicher-Untersystem (400),<br/>
wobei das Speicher-Untersystem (400) eine Schnittstelleneinheit zum Empfangen von Befehlen von dem Verwaltungscomputer (300) über einen Nachrichtenkanal (70) aufweist,<br/>
<b>dadurch gekennzeichnet, daß</b> das Speicher-Untersystem (400) ferner eine Steuereinheit (401) aufweist, die aufgrund eines Sicherheitspegels des Nachrichtenkanals (70) zwischen dem Verwaltungscomputer (300) und dem Speicher-Untersystem (400) bestimmt, ob die Ausführung der Befehle gegenüber einem Teil oder dem gesamten Speicherbereich des Speicher-Untersystems (400) gestattet werden soll, wobei die Steuereinheit (401) aufweist:
<claim-text>einen Speicher (590) zur Speicherung einer ersten Tabelle (1000), in der Sicherheitspegel des Nachrichtenkanals (70) zwischen dem Verwaltungscomputer (300) und dem Speicher-Untersystem (400) vorregistriert sind, und einer zweiten Tabelle (1100), in der Sicherheitspegel vorregistriert sind, die für die Ausführung von Befehlen benötigt werden, deren Ausführung der Verwaltungscomputer (300) von dem Speicher-Untersystem (400) verlangt,</claim-text>
<claim-text>eine erste Einrichtung, die unter Bezugnahme auf die erste Tabelle (1000) für jeden von dem Verwaltungscomputer (300) an das Speicher-Untersystem (400) gesendeten Befehl einen Betriebs-Sicherheitspegel für den Befehl erhält,</claim-text>
<claim-text>eine zweite Einrichtung, die unter Bezugnahme auf die zweite Tabelle (1100) für jeden von dem Verwaltungscomputer (300) an das Speicher-Untersystem (400) gesendeten Befehl einen erforderlichen Sicherheitspegel erhält,</claim-text>
<claim-text>eine dritte Einrichtung, die den über die erste Einrichtung erhaltenen Betriebs-Sicherheitspegel mit dem über die zweite Einrichtung erhaltenen erforderlichen Sicherheitspegel vergleicht, und<!-- EPO <DP n="20"> --></claim-text>
<claim-text>eine vierte Einrichtung, die aufgrund des von der dritten Einrichtung durchgeführten Vergleichs bestimmt, ob die Ausführung des Befehls gestattet werden soll.</claim-text></claim-text></claim>
<claim id="c-de-01-0002" num="0002">
<claim-text>Computersystem nach Anspruch 1, wobei die Steuereinheit (401) des Speicher-Untersystems (400) auch aufgrund des Befehlstyps bestimmt, ob die Ausführung der Befehle gegenüber einem Teil oder dem gesamten Speicherbereich des Speicher-Untersystems (400) gestattet werden soll.</claim-text></claim>
<claim id="c-de-01-0003" num="0003">
<claim-text>Computersystem nach Anspruch 2, wobei der Befehlstyp insbesondere ein zu seiner Durchführung erforderlicher Sicherheitspegel ist.</claim-text></claim>
<claim id="c-de-01-0004" num="0004">
<claim-text>Computersystem nach Anspruch 3, wobei der Sicherheitspegel des Nachrichtenkanals (70) von der Art eines Verschlüsselungsalgorithmus bestimmt ist, der beim Aufbau des Nachrichtenkanals (70) zwischen dem Verwaltungscomputer (300) und dem Speicher-Untersystem (400) gewählt wird.</claim-text></claim>
<claim id="c-de-01-0005" num="0005">
<claim-text>Computersystem nach Anspruch 3, wobei der Sicherheitspegel des Nachrichtenkanals (70) von der Stärke oder Robustheit des Verschlüsselungsalgorithmus bestimmt ist, der beim Aufbau des Nachrichtenkanals (70) zwischen dem Verwaltungscomputer (300) und dem Speicher-Untersystem (400) gewählt wird.</claim-text></claim>
<claim id="c-de-01-0006" num="0006">
<claim-text>Computersystem nach Anspruch 3, wobei der Sicherheitspegel des Nachrichtenkanals (70) von der Schlüssellänge des Verschlüsselungsalgorithmus bestimmt ist, der beim Aufbau des Nachrichtenkanals (70) zwischen dem Verwaltungscomputer (300) und dem Speicher-Untersystem (400) gewählt wird.</claim-text></claim>
<claim id="c-de-01-0007" num="0007">
<claim-text>Computersystem nach Anspruch 3, wobei der zur Ausführung des Befehls erforderliche Sicherheitspegel von der Art der Daten bestimmt ist, die in demjenigen Speicherbereich enthalten sind, auf den sich die auf dem Befehl beruhende Operation bezieht.</claim-text></claim>
<claim id="c-de-01-0008" num="0008">
<claim-text>Computersystem nach Anspruch 3, wobei Befehlen zum Entfernen oder Löschen der Inhalte desjenigen Speicherbereichs, auf den sich die auf ihnen beruhende Operation bezieht, ein höherer Sicherheitspegel für die Ausführung zugeordnet ist als anderen Befehlen.<!-- EPO <DP n="21"> --></claim-text></claim>
<claim id="c-de-01-0009" num="0009">
<claim-text>Computersystem nach Anspruch 4, wobei die erste Tabelle (1000) eine Liste von Verschlüsselungs- und Authentifizierungsalgorithmen, die auf dem Nachrichtenkanal (70) zwischen dem Verwaltungscomputer (300) und dem Speicher-Untersystem (400) benutzt werden, zusammen mit dem jeder Kombination von Verschlüsselungs- und Authentifizierungsalgorithmen zugeordneten Sicherheitspegel enthält.</claim-text></claim>
<claim id="c-de-01-0010" num="0010">
<claim-text>Computersystem nach Anspruch 1, wobei die zweite Tabelle (1100) eine Liste von zwischen dem Verwaltungscomputer (300) und dem Speicher-Untersystem (400) definierten Befehlen zusammen mit einem für die Ausführung jedes dieser Befehle erforderlichen Sicherheitspegel enthält.</claim-text></claim>
<claim id="c-de-01-0011" num="0011">
<claim-text>Computersystem nach Anspruch 1, wobei die vierte Einrichtung die Erlaubnis zur Ausführung eines Befehls erteilt, wenn der von der dritten Einrichtung durchgeführte Vergleich anzeigt, daß der Betriebs-Sicherheitspegel größer oder gleich ist wie der erforderliche Sicherheitspegel.</claim-text></claim>
<claim id="c-de-01-0012" num="0012">
<claim-text>Computersystem nach Anspruch 1, wobei<br/>
in dem Speicher (590) ferner eine dritte Tabelle (1200) gespeichert ist, in der eine Historie der von dem Verwaltungscomputer (300) an das Speicher-Untersystem (400) ausgegebenen Befehle registriert ist, sowie eine vierte Tabelle (1300), die für jede Klientenkennung einen Sicherheitspegel-Anhebungswert enthält, der sich nach einem in der dritten Tabelle (1200) aufgezeichneten Ergebnis der Entscheidung bestimmt, ob die Durchführung gestattet oder abgewiesen wird, und<br/>
die Steuereinheit (401) ferner eine Einrichtung aufweist, die den aus der vierten Tabelle (1300) erhaltenen Sicherheitspegel-Anhebungswert zu dem von der zweiten Einrichtung erhaltenen erforderlichen Sicherheitspegel hinzuaddiert, wobei der so modifizierte erforderliche Sicherheitspegel in dem von der dritten Einrichtung durchgeführten Vergleich benutzt wird.</claim-text></claim>
<claim id="c-de-01-0013" num="0013">
<claim-text>Verfahren zum Verwalten von Zugriffsanforderungen an ein Speicher-Untersystem (400), wobei Befehle von einem Verwaltungscomputer (300) empfangen werden,<br/>
<b>dadurch gekennzeichnet, daß</b> aufgrund eines Sicherheitspegels eines Nachrichtenkanals (70) zu und von dem Verwaltungscomputer (300) sowie eines für die Ausführung der Befehle erforderlichen Sicherheitspegels bestimmt wird, ob<!-- EPO <DP n="22"> --> die Ausführung der Befehle gegenüber einem Speicherbereich des Speicher-Untersystems (400) gestattet werden soll, indem<br/>
eine erste Tabelle (1000), in der Sicherheitspegel des Nachrichtenkanals (70) zwischen dem Verwaltungscomputer (300) und einem Speicher-Untersystem (400) vorregistriert sind, sowie eine zweite Tabelle (1100) gespeichert wird, in der Sicherheitspegel vorregistriert sind, die zur Ausführung von Befehlen erforderlich sind, deren Ausführung der Verwaltungscomputer (300) von dem Speicher-Untersystem (400) verlangt,<br/>
unter Bezugnahme auf die erste Tabelle (1000) für jeden von dem Verwaltungscomputer (300) an das Speicher-Untersystem (400) gesendeten Befehl ein Betriebs-Sicherheitspegel für den Befehl erhalten,<br/>
unter Bezugnahme auf die zweite Tabelle (1100) für jeden von dem Verwaltungscomputer (300) an das Speicher-Untersystem (400) gesendeten Befehl ein erforderlicher Sicherheitspegel erhalten,<br/>
der Betriebs-Sicherheitspegel mit dem erforderlichen Sicherheitspegel verglichen und<br/>
aufgrund des Vergleichsergebnisses bestimmt wird, ob die Ausführung des Befehls gestattet werden soll.</claim-text></claim>
<claim id="c-de-01-0014" num="0014">
<claim-text>Computerprogramm zur Verwaltung von Zugriffsanforderungen auf ein Speicher-Untersystem (400), das bei Ausführung auf dem Speicher-Untersystem (400) das Verfahren nach Anspruch 13 durchführt.</claim-text></claim>
<claim id="c-de-01-0015" num="0015">
<claim-text>Von einem Speicher-Untersystem (400) lesbarer Datenträger, der das Computerprogramm nach Anspruch 14 enthält.</claim-text></claim>
</claims><!-- EPO <DP n="23"> -->
<claims id="claims03" lang="fr">
<claim id="c-fr-01-0001" num="0001">
<claim-text>Système informatique comportant<br/>
un ordinateur (200a, 200b),<br/>
un sous-système de mémorisation (400), et<br/>
un ordinateur de gestion (300) comportant une unité de commande (401) adaptée pour émettre des instructions afin de gérer l'ordinateur (200a, 200b) ou le sous-système de mémorisation (400) et une unité d'interface (304) adaptée pour envoyer les instructions à l'ordinateur (200a, 200b) ou au sous-système de mémorisation (400),<br/>
dans lequel le sous-système de mémorisation (400) comporte une unité d'interface adaptée pour recevoir des instructions en provenance de l'ordinateur de gestion (300) via un trajet de communication (70),<br/>
<b>caractérisé en ce que</b> le sous-système de mémorisation (400) comporte en outre une unité de commande (401) adaptée pour déterminer s'il faut autoriser l'exécution des instructions vis-à-vis d'une partie ou de la totalité de la zone de mémorisation du sous-système de mémorisation (400), sur la base d'un niveau de sécurité du trajet de communication (70) entre l'ordinateur de gestion (300) et le sous-système de mémorisation (400), l'unité de commande 401 incluant :
<claim-text>une mémoire (590) mémorisant un premier tableau (1000) pré-enregistrant des niveaux de sécurité du trajet de communication (70) entre l'ordinateur de gestion (300) et l'ordinateur (200a, 200b) et un deuxième tableau (1100) pré-enregistrant des niveaux de sécurité requis pour l'exécution des instructions que l'ordinateur de gestion (300) demande à l'ordinateur (200a, 200b) d'exécuter,</claim-text>
<claim-text>des premiers moyens pour obtenir, pour chaque instruction envoyée depuis l'ordinateur de gestion (300) à l'ordinateur (200a, 200b), un niveau de sécurité opérationnel<!-- EPO <DP n="24"> --> pour l'instruction en se reportant au premier tableau (1000),</claim-text>
<claim-text>des deuxièmes moyens pour obtenir, pour chaque instruction envoyée depuis l'ordinateur de gestion (300) à l'ordinateur (200a, 200b), un niveau de sécurité requis en se reportant au deuxième tableau (1100),</claim-text>
<claim-text>des troisièmes moyens pour comparer le niveau de sécurité opérationnel obtenu par les premiers moyens et le niveau de sécurité requis obtenu par les deuxièmes moyens, et</claim-text>
<claim-text>des quatrièmes moyens pour déterminer s'il faut autoriser l'exécution de l'instruction sur la base du résultat de la comparaison effectuée par les troisièmes moyens.</claim-text></claim-text></claim>
<claim id="c-fr-01-0002" num="0002">
<claim-text>Système informatique selon la revendication 1, dans lequel l'unité de commande (401) du sous-système de mémorisation (400) est adaptée pour déterminer s'il faut autoriser l'exécution des instructions vis-à-vis d'une partie ou de la totalité de la zone de mémorisation du sous-système de mémorisation (400), également sur la base du type des instructions.</claim-text></claim>
<claim id="c-fr-01-0003" num="0003">
<claim-text>Système informatique selon la revendication 2, dans lequel le type de l'instruction est spécifiquement un niveau de sécurité requis pour son exécution.</claim-text></claim>
<claim id="c-fr-01-0004" num="0004">
<claim-text>Système informatique selon la revendication 3, dans lequel le niveau de sécurité du trajet de communication (70) est déterminé par le type d'algorithme de chiffrement sélectionné pour établir le trajet de communication (70) entre l'ordinateur de gestion (300) et le sous-système de mémorisation (400).</claim-text></claim>
<claim id="c-fr-01-0005" num="0005">
<claim-text>Système informatique selon la revendication 3, dans lequel le niveau de sécurité du trajet de communication (70) est déterminé par la solidité ou la robustesse de l'algorithme de chiffrement sélectionné pour établir le trajet de communication (70) entre l'ordinateur<!-- EPO <DP n="25"> --> de gestion (300) et le sous-système de mémorisation (400).</claim-text></claim>
<claim id="c-fr-01-0006" num="0006">
<claim-text>Système informatique selon la revendication 3, dans lequel le niveau de sécurité du trajet de communication (70) est déterminé par la longueur de clé de l'algorithme de chiffrement sélectionné pour établir le trajet de communication (70) entre l'ordinateur de gestion (300) et le sous-système de mémorisation (400).</claim-text></claim>
<claim id="c-fr-01-0007" num="0007">
<claim-text>Système informatique selon la revendication 3, dans lequel le niveau de sécurité requis pour l'exécution de l'instruction est déterminé par le type de données contenues dans la zone de mémorisation qui est soumise à l'opération basée sur l'instruction.</claim-text></claim>
<claim id="c-fr-01-0008" num="0008">
<claim-text>Système informatique selon la revendication 3, dans lequel un niveau de sécurité supérieur pour l'exécution est attribué à des instructions destinées à supprimer ou à effacer le contenu de la zone de mémorisation qui est soumise à l'opération basée sur celles-ci plutôt qu'à d'autres instructions.</claim-text></claim>
<claim id="c-fr-01-0009" num="0009">
<claim-text>Système informatique selon la revendication 4, dans lequel le premier tableau (1000) liste des algorithmes de chiffrement et des algorithmes d'authentification utilisés sur le trajet de communication (70) entre l'ordinateur de gestion (300) et l'ordinateur (200a, 200b), conjointement avec le niveau de sécurité attribué à chaque combinaison d'algorithmes de chiffrement et d'authentification.</claim-text></claim>
<claim id="c-fr-01-0010" num="0010">
<claim-text>Système informatique selon la revendication 1, dans lequel le deuxième tableau (1100) liste des instructions définies entre l'ordinateur de gestion (300) et l'ordinateur (200a, 200b) conjointement avec un niveau de sécurité requis pour l'exécution de chacune des instructions.</claim-text></claim>
<claim id="c-fr-01-0011" num="0011">
<claim-text>Système informatique selon la revendication 1, dans lequel les quatrièmes moyens sont adaptés pour<!-- EPO <DP n="26"> --> accorder l'autorisation d'exécution d'une instruction lorsque la comparaison effectuée par les troisièmes moyens indique que le niveau de sécurité opérationnel est supérieur ou égal au niveau de sécurité requis.</claim-text></claim>
<claim id="c-fr-01-0012" num="0012">
<claim-text>Système informatique selon la revendication 1, dans lequel<br/>
la mémoire (590) mémoire en outre un troisième tableau (1200) enregistrant un historique des instructions délivrées par l'ordinateur de gestion (300) à l'ordinateur (200a, 200b) et un quatrième tableau (1300) conservant pour chaque ID de client une valeur élevée de niveau de sécurité déterminée conformément à un résultat de détermination, une exécution autorisée ou rejetée, enregistrée dans le troisième tableau (1200), et l'unité de commande (401) comporte en outre :
<claim-text>des moyens pour ajouter la valeur élevée de niveau de sécurité obtenue depuis le quatrième tableau (1300) au niveau de sécurité requis obtenu par les deuxièmes moyens, le niveau de sécurité requis ainsi modifié étant utilisé dans la comparaison effectuée par les troisièmes moyens.</claim-text></claim-text></claim>
<claim id="c-fr-01-0013" num="0013">
<claim-text>Procédé pour gérer des demandes d'accès pour un sous-système de mémorisation (400) comportant les étapes consistant à :
<claim-text>recevoir des instructions en provenance d'un ordinateur de gestion (300),</claim-text>
<b>caractérisé par</b> l'étape consistant à déterminer s'il faut autoriser l'exécution des instructions vis-à-vis d'une zone de mémorisation du sous-système de mémorisation (400), sur la base d'un niveau de sécurité d'un trajet de communication (70) à destination de l'ordinateur de gestion (300) et en provenance de celui-ci et également sur la base d'un niveau de sécurité requis pour l'exécution des instructions, en :<!-- EPO <DP n="27"> -->
<claim-text>mémorisant un premier tableau (1000) pré-enregistrant des niveaux de sécurité du trajet de communication (70) entre l'ordinateur de gestion (300) et un ordinateur (200a, 200b) et un deuxième tableau (1100) pré-enregistrant des niveaux de sécurité requis pour l'exécution des instructions que l'ordinateur de gestion (300) demande à l'ordinateur (200a, 200b) d'exécuter,</claim-text>
<claim-text>obtenant, pour chaque instruction envoyée depuis l'ordinateur de gestion (300) à l'ordinateur (200a, 200b), un niveau de sécurité opérationnel pour l'instruction en se reportant au premier tableau (1000),</claim-text>
<claim-text>obtenant, pour chaque instruction envoyée depuis l'ordinateur de gestion (300) à l'ordinateur (200a, 200b), un niveau de sécurité requis en se reportant au deuxième tableau (1100),</claim-text>
<claim-text>comparant le niveau de sécurité opérationnel et le niveau de sécurité requis,</claim-text>
<claim-text>déterminant s'il faut autoriser l'exécution de l'instruction sur la base du résultat de la comparaison.</claim-text></claim-text></claim>
<claim id="c-fr-01-0014" num="0014">
<claim-text>Programme informatique pour gérer des demandes d'accès pour un sous-système de mémorisation (400), lequel, lorsque exécuté sur le sous-système de mémorisation (400), met en oeuvre le procédé de la revendication 13.</claim-text></claim>
<claim id="c-fr-01-0015" num="0015">
<claim-text>Support de données lisibles par un sous-système de mémorisation (400) et comportant le programme informatique de la revendication 14.</claim-text></claim>
</claims><!-- EPO <DP n="28"> -->
<drawings id="draw" lang="en">
<figure id="f0001" num=""><img id="if0001" file="imgf0001.tif" wi="165" he="212" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="29"> -->
<figure id="f0002" num=""><img id="if0002" file="imgf0002.tif" wi="160" he="233" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="30"> -->
<figure id="f0003" num=""><img id="if0003" file="imgf0003.tif" wi="147" he="160" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="31"> -->
<figure id="f0004" num=""><img id="if0004" file="imgf0004.tif" wi="153" he="233" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="32"> -->
<figure id="f0005" num=""><img id="if0005" file="imgf0005.tif" wi="145" he="194" img-content="drawing" img-format="tif"/></figure>
</drawings>
<ep-reference-list id="ref-list">
<heading id="ref-h0001"><b>REFERENCES CITED IN THE DESCRIPTION</b></heading>
<p id="ref-p0001" num=""><i>This list of references cited by the applicant is for the reader's convenience only. It does not form part of the European patent document. Even though great care has been taken in compiling the references, errors or omissions cannot be excluded and the EPO disclaims all liability in this regard.</i></p>
<heading id="ref-h0002"><b>Patent documents cited in the description</b></heading>
<p id="ref-p0002" num="">
<ul id="ref-ul0001" list-style="bullet">
<li><patcit id="ref-pcit0001" dnum="EP1255179A2"><document-id><country>EP</country><doc-number>1255179</doc-number><kind>A2</kind></document-id></patcit><crossref idref="pcit0001">[0006]</crossref></li>
<li><patcit id="ref-pcit0002" dnum="US20030115447A1"><document-id><country>US</country><doc-number>20030115447</doc-number><kind>A1</kind></document-id></patcit><crossref idref="pcit0002">[0007]</crossref></li>
</ul></p>
</ep-reference-list>
</ep-patent-document>
